Session Fixation in snipe/snipe-it


Reported on

Aug 22nd 2022


The session is not invalidated after a password change.

Proof of Concept

Open Snipe-IT in the browser and login. Do the same in a private window such that there are two sessions. Change the password in one of the two sessions and observe that the second session is not invalidated.


An old session can be used even after the password has been changed.

We are processing your report and will contact the snipe/snipe-it team within 24 hours. a month ago
We have contacted a member of the snipe/snipe-it team and are waiting to hear back a month ago
snipe validated this vulnerability a month ago
vautia has been awarded the disclosure bounty
The fix bounty is now up for grabs
The researcher's credibility has increased: +7
snipe confirmed that a fix has been merged on 6fde72 a month ago
snipe has been awarded the fix bounty
to join this conversation